Windows_Trojan_CobaltStrike_15f680fb
Description
Identifies Netview module from Cobalt Strike
Query · yara
strings:
$a1 = "netview.x64.dll" ascii fullword
$a2 = "netview.dll" ascii fullword
$a3 = "\\\\.\\pipe\\netview" ascii fullword
$b1 = "Sessions for \\\\%s:" ascii fullword
$b2 = "Account information for %s on \\\\%s:" ascii fullword
$b3 = "Users for \\\\%s:" ascii fullword
$b4 = "Shares at \\\\%s:" ascii fullword
$b5 = "ReflectiveLoader" ascii fullword
$b6 = "Password changeable" ascii fullword
$b7 = "User's Comment" wide fullword
$b8 = "List of hosts for domain '%s':" ascii fullword
$b9 = "Password changeable" ascii fullword
$b10 = "Logged on users at \\\\%s:" ascii fullword
condition:
2 of ($a*) or 6 of ($b*)